CVE Explorer
CVE-2026-27639
Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Scripting (XSS) vulnerability exists in Mercator prior to version 2026.02.22 due to the use of unescaped Blade directives (`{!! !!}`) in display templates. An authenticated user with the User role can inject arbitrary JavaScript payloads into fields such as "contact point" when creating or editing entities. The payload is then executed in the browser of any user who views the affecte
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mercator","vendor":"dbarzin","versions":[{"status":"affected","version":"< 2026.02.22"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6cbbf60e0ebd83823e5f25d350dbd1c3cbdc6cc984cf2fac8c2abd3c652a031f · sha256:2cf41582212f66fc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.5,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6cbbf60e0ebd83823e5f25d350dbd1c3cbdc6cc984cf2fac8c2abd3c652a031f · sha256:2cf41582212f66fc… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6cbbf60e0ebd83823e5f25d350dbd1c3cbdc6cc984cf2fac8c2abd3c652a031f · sha256:2cf41582212f66fc… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/dbarzin/mercator/commit/839d231399944e43a865198262e96e0218252cc3","tags":["x_refsource_MISC"],"url":"https://github.com/dbarzin/mercator/commit/839d231399944e43a865198262e96e0218252cc3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6cbbf60e0ebd83823e5f25d350dbd1c3cbdc6cc984cf2fac8c2abd3c652a031f · sha256:2cf41582212f66fc… · /containers/cna/references/1
{"name":"https://github.com/dbarzin/mercator/commit/9902ffd91f287e474729f514c77261f4ef7db8fe","tags":["x_refsource_MISC"],"url":"https://github.com/dbarzin/mercator/commit/9902ffd91f287e474729f514c77261f4ef7db8fe"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6cbbf60e0ebd83823e5f25d350dbd1c3cbdc6cc984cf2fac8c2abd3c652a031f · sha256:2cf41582212f66fc… · /containers/cna/references/2
{"name":"https://github.com/dbarzin/mercator/commit/c58bb1d2fff18605c61d93cfaf77adca416c560a","tags":["x_refsource_MISC"],"url":"https://github.com/dbarzin/mercator/commit/c58bb1d2fff18605c61d93cfaf77adca416c560a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6cbbf60e0ebd83823e5f25d350dbd1c3cbdc6cc984cf2fac8c2abd3c652a031f · sha256:2cf41582212f66fc… · /containers/cna/references/3
{"name":"https://github.com/dbarzin/mercator/security/advisories/GHSA-65p7-pph2-966g","tags":["x_refsource_CONFIRM"],"url":"https://github.com/dbarzin/mercator/security/advisories/GHSA-65p7-pph2-966g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6cbbf60e0ebd83823e5f25d350dbd1c3cbdc6cc984cf2fac8c2abd3c652a031f · sha256:2cf41582212f66fc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.